CVE-2026-84518
MEDIUMDescription
This issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious website may be able to determine what apps a user has installed.
Is your site exposed to CVE-2026-84518?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| apple | safari |
| apple | ipados |
| apple | iphone_os |
| apple | macos |
References
Frequently Asked Questions
What is CVE-2026-84518? +
How severe is CVE-2026-84518? +
What products are affected by CVE-2026-84518? +
How do I check if I'm vulnerable to CVE-2026-84518? +
Related Vulnerabilities
Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie …
The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state …
External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated …
An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, …
An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CLI …
An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, …